VDB
CVE-2018-1075
CVE-2018-1075
PUBLISHED
CVSS 5 MEDIUM
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.
EPSS 0.39% · 32.2th percentile
Risk Scores
CVSS 3.0
5
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.39%
32.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ovirt | ovirt | 0 |
| [UNKNOWN] | ovirt-engine | up to ovirt-engine 4.2.3 |
Timeline
- Jun 12, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- May 13, 2022 CVE Updated
- Jul 4, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1075 url
- https://gerrit.ovirt.org/#/c/91653/ url
- https://access.redhat.com/errata/RHSA-2018:2071 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1075 advisory
- https://access.redhat.com/security/cve/CVE-2018-1075 url
- https://bugzilla.redhat.com/show_bug.cgi?id=1542508 url
- https://gerrit.ovirt.org/#/c/91653 url